Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.0% | — | Cisco Content Services Switch 11500 | 2/11/2005 | 16/6/2026 | Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Invision Power Services Invision Gallery | 1/11/2005 | 16/6/2026 | SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter. | |
| Modificada | Media (5) | 42% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 23/8/2005 | 16/6/2026 | Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Invision Power Services Invision Board | 10/8/2005 | 16/6/2026 | Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML. | |
| Modificada | Media (4.3) | 31% | — | Microsoft Internet Information Services | 5/7/2005 | 16/6/2026 | Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a… | |
| Modificada | Alta (7.5) | 25% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+3 | 14/6/2005 | 16/6/2026 | El desbordamiento de búfer en Microsoft Step-by-Step Interactive Training (orun32.exe) permite a los atacantes remotos ejecutar código arbitrario a través de un archivo de enlace de marcadores (extensión.cbo, cbl o.cbm) con un campo de usuario largo. | |
| Modificada | Media (5.1) | 13% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+3 | 14/6/2005 | 16/6/2026 | Microsoft Agent permite a los atacantes remotos falsificar contenido de Internet de confianza y ejecutar código arbitrario disfrazando las indicaciones de seguridad en una página web maliciosa. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Invision Power Services Invision Gallery | 9/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 9/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | |
| Modificada | Media (4.3) | 1.2% | — | Invision Power Services Invision Community Blog | 9/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data. | |
| Modificada | Alta (7.4) | 16% | 💥 PoC | Microsoft Remote Desktop ConnectionMicrosoft Windows Terminal Services Using RDP | 1/6/2005 | 16/6/2026 | Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks. | |
| Modificada | Media (4.6) | 0.50% | — | Invision Power Services Invision Board | 1/6/2005 | 16/6/2026 | Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen. | |
| Modificada | Media (5) | 1.9% | 💥 Exploit | Invision Power Services Invision Board | 1/6/2005 | 16/6/2026 | Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 16/5/2005 | 16/6/2026 | SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable. | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Firewall Services Module | 11/5/2005 | 16/6/2026 | Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs). | |
| Modificada | Media (4.6) | 0.59% | — | HP Openview Event Correlation Services | 3/5/2005 | 16/6/2026 | Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Media (4.3) | 20% | — | Microsoft Sharepoint Portal ServerMicrosoft Sharepoint Team Services | 2/5/2005 | 16/6/2026 | Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Invision Power Services Invision Board | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Media (5) | 1.2% | — | IRC Services Nickserv Listlinks | 2/5/2005 | 16/6/2026 | Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Invision Power Services Invision Board | 11/4/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision Power Board | 30/3/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en el código SML de Invision Power Board 1.3.1 FINAL permite a atacantes remotos la inyección de sripts arbitrarios mediante: un fichero de firmas, un mensaje que contiene una etiqueta IMG en una etiqueta COLOR cuyo estilo está puesto como background:url. | |
| Modificada | Alta (7.5) | 23% | — | Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+6 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. |